HomeSecurityVMware fixes Spring4Shell vulnerability affecting several of its products

VMware patches Spring4Shell vulnerability affecting several of its products

VMware has released security updates to fix a critical remote code execution vulnerability known as Spring4Shell that affects several of the company's cloud computing and virtualization products.

In the security advisory published by the company, it lists the list of VMware products affected by the Spring4Shell vulnerability. Where a fix is ​​not available, VMware has provided some protection advice as a temporary solution.

See also: Amazon: Phishing email threatens to permanently block accounts

VMware Spring4Shell

Serious vulnerability in Spring Framework

The Spring4Shell vulnerability, officially known as CVE-2022-22965 , is a remote code execution vulnerability found in the Spring Core Java framework . It can execute code without authentication and has been rated 9.8/10 on the vulnerability severity scale.

According to experts, any malicious user with access to vulnerable applications can execute commands and take full control of a target system.

The Spring Framework is very popular for developing Java applications, so security analysts fear that many criminals are exploiting the Spring4Shell vulnerability. In addition, a proof-of-concept (PoC) exploit has been leaked on GitHub ahead of the security update's release.

See also: Android malware: New spyware has access to a lot of data

The vulnerability affects Spring MVC and Spring WebFlux apps running on JDK 9+. The exploit requires the application to be running on Tomcat as a WAR deployment, although the exact restrictions are still under investigation.

The fixed versions of the applications are:

  • Spring Framework 5.3.18 and Spring Framework 5.2.20
  • Spring Boot 2.5.12
  • Spring Boot 2.6.6 (coming soon)

VMWare has reviewed its products and, while the investigation is still ongoing, has reported that the following products are affected by the Spring4Shell vulnerability:

  1. VMware Tanzu Application Service for VMs – versions 2.10 to 2.13
  2. VMware Tanzu Operations Manager – versions 2.8 to 2.9
  3. VMware Tanzu Kubernetes Grid Integrated Edition (TKGI) – versions 1.11 to 1.13
VMware patches Spring4Shell vulnerability affecting several of its products

The company has security updates ready for the first two products, but a permanent fix for VMware Tanzu Kubernetes Grid Integrated Edition is not yet available.

For these deployments, VMWare has published some guidance to help administrators temporarily secure their systems until official updates are released.

See also: Borat malware: New RAT allows DDoS and ransomware attacks

According to VMWare, the Spring4Shell exploit is complex in TKGI, but an update will be released soon.

VMware

VMware, Inc. is an American technology company, headquartered in California, focused on cloud computing and virtualization.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS